Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 3Objective 3

Advanced Persistent Threats (APTs) TIE Practice Questions (Page 8)

Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.

42questions here
9free pages
6concepts

Questions 36–40

  1. 36application · medium

    A security architect is reviewing the 2020 SolarWinds attack, where attackers compromised the software build environment and inserted malicious code into a trusted update. The attackers then used the backdoor to access multiple high-value targets. The architect wants to apply lessons learned to their organization's software supply chain. Which measure is most directly aligned with the lessons from this case study?

    Select an answer first
  2. 37application · medium

    A security manager is reviewing a report about a cyber incident. The report describes an attacker who used a zero-day exploit to gain initial access, then installed a backdoor that survived multiple system reboots, and finally spent six months silently collecting intellectual property. Which characteristic of an APT is most clearly demonstrated by the backdoor surviving reboots?

    Select an answer first
  3. 38application · medium

    During an incident response engagement, a forensics analyst reconstructs the following attack timeline: (1) an attacker scanned the organization's external network, (2) the attacker sent a spear-phishing email to an employee, (3) the employee opened the attachment and the attacker gained a foothold, (4) the attacker escalated privileges using a local vulnerability, (5) the attacker accessed a file server and copied sensitive documents, and (6) the attacker transferred the documents to an external server. The analyst wants to identify the stage where the attacker's objective of data theft was achieved. Which stage is most directly associated with the attacker's objective?

    Select an answer first
  4. 39foundation · easy

    In the typical APT lifecycle, which stage directly follows the initial compromise and is focused on establishing a reliable foothold?

    Select an answer first
  5. 40application · medium

    A security analyst is investigating a potential APT and finds that an attacker has been using a legitimate remote administration tool (RAT) to control a server. The analyst also notices that the attacker has been creating new user accounts with administrative privileges. Which stage of the APT lifecycle does the creation of new user accounts most directly represent?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.